• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

The Best Security Consultants

Menu
  • Industries
      • Aviation and Airport Security Consultants Australia
      • Defence Industry Security Consulting
      • Government Security Consulting
      • Healthcare & Hospitals Security Consulting
      • Corrections and Detention
      • Maritime Security Consultant
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • School and Education Security Consultant
      • Telecommunications Security Consultant
      • Utilities
      • Places of Faith and Worship
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity Consultants
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Cyber Audits
      • Data
      • Pandemic Planning
      • Azure
      • Electronic Security
      • IT Disaster Recovery Planning
      • Business Continuity Consultants
      • Identity Theft Consultant​
      • Security Consultants
      • Security Camera and CCTV Consultant
      • ISO
      • Duress Alarms
      • Cloud
      • AWS
      • Awareness Training
      • Penetration Testing
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Locations
    • Security Consultant Melbourne
    • Security Consultant Sydney
    • Security Consultant Brisbane
    • Security Consultant Adelaide
    • Security Consultant Canberra
    • Security Consultant Perth
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

WordPress Sites Hacked and Scam Online Stores Created

You are here: Home / Security News / WordPress Sites Hacked and Scam Online Stores Created

E-commerce and online activity have grown exponentially, year-on-year. Bricks and mortar stores have increasingly been migrating their products/services to the Internet, which caters to a larger target market then their physical in-store counterpart. However, a recent hack by a new cybercrime gang has caused some ecommerce WordPress sites to generate a scam to their customers.

A security analyst has discovered this hacking method by setting up a honeypot WordPress site, which was then hacked by the group. The attack involved a brute-force attack which gave the hackers access to the site’s admin account, allowing them to overwrite the main index file and append malicious code onto the site. The aim of the malicious code, according to the security analyst, was to divert incoming traffic to the original site towards a remote command and control (C&C) server managed by the hackers.

A step-by-step attack

  1. User visits the hacked site;
  2. The WordPress site redirects the user to the C&C server;
  3. If the user fits the criteria, the C&C server will reply with a fake HTML version of the online store;
  4. The user will be directed to view the fake page of the online store.

SEO also in danger

Not only were the hackers redirecting customers to over 7,000 scam online stores, but they were also utilizing each site’s XML sitemap, which was sent to Google’s search engine, then deleted to avoid detection. While this may seem like a harmless process, the site’s ranking on Google can then start to decline, which could lead to SEO extortion schemes in the future.

To find out more about how to stay secure online and in your bricks and mortar store, contact us at Agilient for the latest in security consultation.

Tweet
Share

Security News

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2025 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692

Our Services

Security Consultant

Security Consultant Sydney

Security Consultant Melbourne

Security Consultant Canberra
Security Consultant Perth

Security Consultant Adelaide

Security Consultant Brisbane